VYPR

Dedecms

by Dedecms

Source repositories

CVEs (173)

  • CVE-2018-10375CriApr 25, 2018
    risk 0.64cvss 9.8epss 0.01

    A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is…

  • CVE-2018-9175CriApr 2, 2018
    risk 0.64cvss 9.8epss 0.02

    DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.

  • CVE-2018-9174CriApr 2, 2018
    risk 0.64cvss 9.8epss 0.01

    sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.

  • CVE-2017-17730CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.01

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

  • CVE-2018-7700HigMar 27, 2018
    risk 0.63cvss 8.8epss 0.75

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

  • CVE-2024-33749CriMay 6, 2024
    risk 0.59cvss 9.1epss 0.01

    DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

  • CVE-2018-20129HigDec 13, 2018
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by…

  • CVE-2026-29839HigMar 24, 2026
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.

  • CVE-2024-30855HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

  • CVE-2024-46373HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

  • CVE-2024-28673HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.

  • CVE-2024-28671HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.

  • CVE-2024-28684HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php

  • CVE-2024-28675HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php

  • CVE-2024-28665HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php

  • CVE-2024-28432HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.

  • CVE-2024-28431HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

  • CVE-2023-52047HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

  • CVE-2024-22895HigJan 22, 2024
    risk 0.57cvss 8.8epss 0.01

    DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

  • CVE-2023-43275HigNov 16, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.

Page 2 of 9